Hijack This logfile (first post to this board)

Status
Not open for further replies.
Five days ago I started working on a friend's computer. Knew I was in trouble when I saw the green dots floating across the screen just after POST (no SP2 upgrade).

He had no anti-virus program, no firewall, no nothin'.

Installed AVG anti virus, ran it, found 11 viruses, trojan horses, hijackers--you name it--and killed them. Installed Spybot, AdAware, and CWShredder, which identified about 400 instances of spyware. But none could kill 'em. Each would SAY it had fixed what it had found, but upon running the same program immediately afterwards, there they (still) were. Hmmm....

Read in the November issue of CPU (Computer Power User) magazine about a program called Zappit System Cleaner. Downloaded, installed it, ran it--it did the job, and let Spybot and Adaware do theirs.

Got all (about 65) Windows updates. All of 'em installed except one. Haven't figured that one out yet. Has to do with "16-bit MS-DOS Subsystem", and the Microsoft information on Q324767 will probably be of some help once I can get to it.

So it's running much better, but still isn't right. I've attached the HijackThis logfile, and am hoping that someone will be able to tell me if there's still a problem with this thing.

Hey, just because I read CPU doesn't mean I AM one (a Power User).
 
Hello and welcome to Techspot.

That system is still full of nasties.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

explorer32.exe

Bus.exe
Rjk.exe
Tcf.exe

Tuh.exe
Pnr.exe
Hhi.exe

Lsp.exe
Fum.exe
Teh.exe

Obs.exe
Bsp.exe
Agf.exe

Kmg.exe
Onb.exe
Trd.exe

Gaf.exe
Cml.exe
Sdu.exe

Vhr.exe
Jum.exe
Mfd.exe

Aat.exe
Kid.exe
Kav.exe

Klg.exe
Ssr.exe
Rds.exe

Gft.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.top-search.us/index.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.top-search.us/search.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.top-search.us/index.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.top-search.us/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.top-search.us/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.top-search.us/search.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.top-search.us/index.html

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;

O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)

O4 - HKLM\..\Run: [Win32 Time Zone] C:\WINDOWS\System32\explorer32.exe

O4 - HKCU\..\Run: [Obi] C:\WINDOWS\System32\Bus.exe

O4 - HKCU\..\Run: [Win32SystemMonitor] C:\WINDOWS\Rjk.exe

O4 - HKCU\..\Run: [Jkb] C:\WINDOWS\Tcf.exe

O4 - HKCU\..\Run: [Ipb] C:\WINDOWS\System32\Tuh.exe

O4 - HKCU\..\Run: [Kdg] C:\WINDOWS\Pnr.exe

O4 - HKCU\..\Run: [Fce] C:\WINDOWS\Hhi.exe

O4 - HKCU\..\Run: [Eov] C:\WINDOWS\System32\Lsp.exe

O4 - HKCU\..\Run: [Sge] C:\WINDOWS\System32\Fum.exe

O4 - HKCU\..\Run: [Qmg] C:\WINDOWS\System32\Teh.exe

O4 - HKCU\..\Run: [Gmr] C:\WINDOWS\Obs.exe

O4 - HKCU\..\Run: [Ofg] C:\WINDOWS\System32\Bsp.exe

O4 - HKCU\..\Run: [Boi] C:\WINDOWS\Agf.exe

O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\System32\Kmg.exe

O4 - HKCU\..\Run: [Loj] C:\WINDOWS\System32\Onb.exe

O4 - HKCU\..\Run: [Csn] C:\WINDOWS\System32\Trd.exe

O4 - HKCU\..\Run: [Kqq] C:\WINDOWS\Gaf.exe

O4 - HKCU\..\Run: [Mnv] C:\WINDOWS\Cml.exe

O4 - HKCU\..\Run: [Ujd] C:\WINDOWS\System32\Sdu.exe

O4 - HKCU\..\Run: [Beg] C:\WINDOWS\Vhr.exe

O4 - HKCU\..\Run: [Grd] C:\WINDOWS\System32\Jum.exe

O4 - HKCU\..\Run: [Sso] C:\WINDOWS\Mfd.exe

O4 - HKCU\..\Run: [Lgn] C:\WINDOWS\System32\Aat.exe

O4 - HKCU\..\Run: [Vve] C:\WINDOWS\Kid.exe

O4 - HKCU\..\Run: [Gpc] C:\WINDOWS\System32\Kav.exe

O4 - HKCU\..\Run: [Rdd] C:\WINDOWS\System32\Klg.exe

O4 - HKCU\..\Run: [Cqp] C:\WINDOWS\Ssr.exe

O4 - HKCU\..\Run: [Jfu] C:\WINDOWS\System32\Rds.exe

O4 - HKCU\..\Run: [Tda] C:\WINDOWS\System32\Gft.exe

O4 - HKCU\..\Run: [Win32 Time Zone] C:\WINDOWS\System32\explorer32.exe

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\WINDOWS\System32\Bus.exe
C:\WINDOWS\Rjk.exe
C:\WINDOWS\Tcf.exe

C:\WINDOWS\System32\Tuh.exe
C:\WINDOWS\Pnr.exe
C:\WINDOWS\Hhi.exe

C:\WINDOWS\System32\Lsp.exe
C:\WINDOWS\System32\Fum.exe
C:\WINDOWS\System32\Teh.exe

C:\WINDOWS\Obs.exe
C:\WINDOWS\System32\Bsp.exe
C:\WINDOWS\Agf.exe

C:\WINDOWS\System32\Kmg.exe
C:\WINDOWS\System32\Onb.exe
C:\WINDOWS\System32\Trd.exe

C:\WINDOWS\Gaf.exe
C:\WINDOWS\Cml.exe
C:\WINDOWS\System32\Sdu.exe

C:\WINDOWS\Vhr.exe
C:\WINDOWS\System32\Jum.exe
C:\WINDOWS\Mfd.exe

C:\WINDOWS\System32\Aat.exe
C:\WINDOWS\Kid.exe
C:\WINDOWS\System32\Kav.exe

C:\WINDOWS\System32\Klg.exe
C:\WINDOWS\Ssr.exe
C:\WINDOWS\System32\Rds.exe

C:\WINDOWS\System32\Gft.exe
C:\WINDOWS\System32\explorer32.exe

Reboot into normal mode, turn system restore back on and rehide your protected OS files.

Post a fresh HJT log.


Regards Howard :wave: :wave:

This thread is for the use of 3DTD only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Thanks, Howard

Really appreciate your taking the time to post such a detailed reply.

I'd already turned off the System Restore, but that's as far as I'd gone. I'll try following your instructions to the letter when I get back home (goofing off at work now) tonight, and will let you know the results.

Mark
 
new HJT logfile

Howard,

I followed your intructions--please see attached logfile.

Running much better, thanks again.

See anything else amiss?

Regards,
Mark
 
Your HJT log is now clean.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of 3DTD only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Status
Not open for further replies.
Back